SBCT_OPSEC_with_PEO_Plan_2013.pdf
PDF 3 MB Posted
- Attached to
- Periscope Hoursing Federal contract opportunity
- Solicitation number
- SPRDL116R0093
About this file
Stryker OPSEC Plan
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SPRDL116R0093-0007.pdf | ||
| SPRDL116R0093-0006.pdf | ||
| SPRDL1-16-R-0093_Periscope_Housing_DD254.pdf | ||
| SPRDL116R0093-0005.pdf | ||
| SPRDL116R0093-0004.pdf | ||
| SPRDL116R0093-0003.pdf | ||
| SPRDL116R0093-0002.pdf | ||
| SPRDL116R0093-0001.pdf | ||
| SPRDL116R0093.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Program Executive Office
Ground Combat Systems (PEO GCS) Operations Security (OPSEC) Plan
14 March 2013
PREPARED BY: Security Office, PEO GCS, SFAE-GCS-CIO/ms 505, 6501 East Eleven Mile Road, Warren, MI 48397-5000
OPERATIONS SECURITY (OPSEC) PLAN
VERSION 1.0
14 MARCH 2013
SUBMITTED BY
NANCY CHAPLIN
Senior Security Officer
APPROVAL
SCOTT J. DAVIS
Program Executive Officer, Ground Combat Systems
PEO GCS OPSEC P lan
Version 1.0 14 March 2013
Change History
OPSEC Plan Control Information
Document ID:
GCS_ OPSEC_Plan
Document Owner:
Security Officer
Document Approver:
PEO
Date Effective:
20130314
Version:
1.0
Retention Period:
Review Annual
Archive Location:
PEO GCS Portal
The following Change History log contains a record of changes made to this document:
Published / Revised Date
Version
Author (optional)
Section / Nature of Change
03/14/2013 1.0 Chaplin, Nancy Initial i
Table of Contents
PEO GCS Mission Statement
Assignment of OPSEC Responsibilities OPSEC Definition
OPSEC Concept
OPSEC Compromise
Penalties
Limits on Secrecy
Individual Responsibilities
Program Executive Officer (PEO)
Senior Security Officer
OPSEC Officer
Public Affairs Officer (PAO)
PEO Webmaster
Project Managers (PM)
Assistant Program Executive Officers
All personnel
OPSEC Considerations
Critical Information
OPSEC Measures OPSEC Awareness
Administrative/Personnel
Waste Disposal
Conferences/Symposia
Conference Room Security
Unsolicited Requests for Information
Compromising Emanations
Communications Security
Computer Security
Employee Travel
Shipment of Sensitive Materials
Public Release
Web site OPSEC Reviews
Employee Disaffection
Document Markings
Protection Measures for CUI
Visitor Control
Escorts for Foreign Visitors
Contractor and Subcontract Requirements
Annex A – The Intelligence Collection Threat Foreign Intelligence Service Threat
Terrorist Threat
Insider Threat
Criminal Threat (Outsider)
Environmental Threat ii
Military Threat
Human Intelligence (HUMINT)
Signals Intelligence (SIGINT)
Measurement and Signatures Intelligence (MASINT)
Imagery Intelligence (IMINT)
Open Source Intelligence (OSINT)
Computer Intrusion for Collection Operations
Terrorism
Technology Transfer
Professional Conferences/Symposiums
Personnel Disaffection
Annex B – Vulnerability Assessment Information Security Vulnerabilities
Operations Security Vulnerabilities
Physical Security Vulnerabilities
Information System (IS) Vulnerabilities
Annex C – PEO OPSEC Program Matrix
Annex D – OPSEC Checklist
Annex E – Terms
Annex F – References
PEO GCS Mission Statement
Execute life cycle management of the world’s best ground combat systems in a collaborative learning environment by developing, acquiring, and supporting modernized and affordable systems with common integrated capabilities, always focusing on the needs of the Joint Warfighter.
Assignment of OPSEC Responsibilities
This publication specifically addresses the common features of a functional, active and documented Operations Security (OPSEC) program. This publication assigns OPSEC responsibilities and requirements within the Program Executive Office, Ground Combat Systems (PEO GCS) to plan for and implement OPSEC; a systematic approach to developing necessary OPSEC measures; implementation of OPSEC training;
requirements for the review of OPSEC measures and reporting; and cross-command and interagency support to the PEO GCS OPSEC program, which includes reviews, assessments, and survey training. It is designed to provide a basic understanding of OPSEC functions and how to apply them within PEO GCS. Each Project Management Office (PMO) of the PEO may require a unique approach to OPSEC depending on the PMO function. Each PMO will write an OPSEC Plan to address considerations not addressed in this PEO Plan. The basic concepts set forth herein are essentially the same for every organizational element of the PEO. OPSEC is applicable to all aspects of work, from daily routine planning through testing, exercise, and evaluation phases to force deployment, recovery, and reconstitution.
PEO OPSEC Officer: Nancy Chaplin, 586-282-9648
This OPSEC Plan documents the policies and procedures needed to meet the specific OPSEC program requirements of PEO GCS and to support the OPSEC programs of higher echelons.
The overall purpose of OPSEC is to strengthen our traditional security procedures by identifying existing vulnerabilities or weaknesses and applying measures to protect sensitive technologies. The goal is to deny our adversaries access to any critical information. Critical information includes technologies and information desired by an adversary that is sensitive and the disclosure of which could seriously impact our programs. Technology or information does not have to be classified to be of value to an adversary. An adversary can learn a lot about our programs by piecing together obtainable unclassified information. Therefore, in our attempts to shield our activities, it is not only important to follow normal security practices but also to implement OPSEC measures. This OPSEC Plan will discuss the five-step process:
1. Identifying Critical Information
2. Analysis of Threats
3. Analysis of Vulnerabilities
4. Assessment of Risks
5. Application of OPSEC Measures.
OPSEC applies to all organizations within PEO GCS. All information identified as critical information will be reviewed for OPSEC before being released to Government agencies outside PEO GCS. All information, regardless of whether it is critical, will be reviewed for OPSEC before its release to the public in any manner.
OPSEC Definition
OPSEC is a process of identifying critical information and subsequently analyzing friendly actions attendant to military operations and other activities to—
1. Identify actions that can be observed by adversary intelligence systems.
2. Determine indicators that hostile intelligence systems can obtain that could be interpreted or pieced together to derive critical information in time to be useful to adversaries.
3. Select and execute measures that eliminate or reduce to an acceptable level the vulnerabilities of friendly actions to adversary exploitation.
OPSEC Concept
Many activities normal to daily functioning will convey information and indicators to adversaries in spite of routine security measures (personnel, physical, document, cryptographic, computer) to protect classified information. Information available from detectable friendly activities, when combined with other information held by an adversary will, in unknown ways, shape the adversary's appreciations and perceptions of friendly intentions, military capabilities, actions, and possible weaknesses, all of which will provide answers to adversary intelligence questions. During classified or sensitive unclassified undertakings (e.g., operations, exercises, field tests of military systems), acting routinely can result in adversaries gaining harmful appreciations by piecing together observable critical indicators.
Intelligence systems function worldwide. Even if PEO GCS is vigilant, other organizations that provide support may conduct activities that convey pertinent PEO GCS information or indicators of intentions, capabilities, limitations, and vulnerabilities.
Therefore, planning for primary and supporting operations and other activities (e.g., a test administered by the Army Test and Evaluation Command [ATEC]) must include systematic examination to determine potential disclosures that would cause cancellation or failure of the primary undertaking. Subsequently, one must plan and execute protective measures that permit operations and activities to proceed effectively while preserving requisite essential secrecy. OPSEC is the process designed to do this.
An OPSEC vulnerability exists when an adversary can collect indicators of critical information, process the information, and react in a way harmful to the United States.
The most serious problem facing PEO GCS in this respect is that critical information collected by an adversary today may allow the adversary to develop a technological advantage in the future. Collection capabilities used to obtain information from accessible activities generally depend on some form of target cooperation. For example, throwing any information in the trash allows it to be retrieved by an adversary who will gain information about our activities, and releasing information into the public domain allows the adversary to obtain useable information at no risk to their assets. The detection of predictable actions depends on our acting in stereotyped ways. Thus, if proper OPSEC measures are applied, it is often possible to eliminate or control many detectable indicators of critical information about our intentions, capabilities, limitations, and activities. Remember; trash cans are for non-informational items only (e.g., food waste, wrappers). All unclassified informational material will be placed in the secure shred boxes located throughout PEO GCS facilities.
The key objective of OPSEC is to ensure mission effectiveness. Some protective measures to eliminate information conveyed by an activity may unacceptably reduce effectiveness. For example, telemetry and communications are often needed in tests;
and personnel, equipment, and material movements are unavoidable in the execution of operations and other activities. In these instances, it may be possible to deny information by acting against the collectors or analysts, rather than stopping the actions.
Denial actions include the use of jamming, obscurants, weather, camouflage, environmental conditions, covers, or military deception (MD) to influence adversary perceptions and conclusions (e.g., cover operations to explain observable activities, diversions to draw collection and analytical interest elsewhere, creating conditioning to cause activities to be ignored, multiple impressions to confuse interpretation of information). In Joint operations, OPSEC is an element of command and control warfare (C2W). Countering the adversary command and control (C2), and protecting friendly C2 are functions of OPSEC.
Planning for secrecy must extend beyond exposure of raw information and consider possible assumptions and estimates made by an adversary. Logical conclusions based on generally available information, trend analysis based on historical data or technical possibilities, and broad experience of adversary planners and decision makers must be factored in to planning. Military deception may be required to mislead adversary analysts to maintain essential secrecy.
The following are examples of unclassified information that could alert an adversary to the existence of a classified project, existence or application of advanced technology, or a new tactic or technique unknown to adversaries:
Unclassified agreements between government agencies or their association in a project or operation that outlines methods, procedures, and current U.S.
Government intentions or future objectives.
Special or unique requests providing special instructions that could reveal capabilities or the technology of a new weapon system.
Public relations release describing aspects of technological or operational cooperation between the U.S. and other nations.
Announcements of formation of specialized groups, special elements, or organizations, which could signal special intentions, activities, or capabilities.
Consolidated budget execution for specific projects, testing of items or tactics, and monies spent that are intended for future acquisition.
OPSEC Compromise
An OPSEC compromise is the disclosure of critical or sensitive information that jeopardizes PEO GCS’s ability to execute its mission or to adequately protect its personnel or equipment. Good OPSEC practices can prevent these compromises and allow us to maintain essential secrecy about our operations.
Critical or sensitive information that has been compromised and is available in open sources and the public domain should not be highlighted or referenced publicly outside of intragovernmental or authorized official communications, because these actions provide further unnecessary exposure of the compromised information. Report any known or suspected OPSEC compromise to the PEO Security Office immediately.
Penalties
Failure to comply with these orders, directives, or policies may be punished as violations of a lawful order under Article 92 of the Uniform Code of Military Justice (UCMJ) or under other disciplinary, administrative, or other actions as applicable.
Personnel not subject to the UCMJ who fail to protect critical and sensitive information from unauthorized disclosure may be subject to administrative, disciplinary, contractual, or criminal action.
Limits on Secrecy
Take care in determining the required degree of secrecy for undertakings. Too much secrecy can harm effectiveness; too little can result in mission or system failure. Broad factors to consider include the following:
Adversaries must have some knowledge of friendly capabilities and intentions so they will perceive threats.
The public must have some knowledge of military capabilities to foster recruitment of required personnel, gain internal political support, ensure understanding of defense budgeting requests, and support defense alliances.
The U.S. must rigorously test systems, procedures, doctrine, and tactics in realistic environments.
Planners must thoroughly understand activities to realize optimal coordination and effectiveness of their undertakings.
http://www.au.af.mil/au/awc/awcgate/ucmj.htm
Individual Responsibilities
Every individual is ultimately responsible for the security of the information to which he or she has access. Each piece of information that an adversary can get access to fills in one more piece of the puzzle as it relates to our overall plan of action.
Program Executive Officer
Issue orders, directives, and policies to protect PEO GCS critical and sensitive information to clearly define the specific OPSEC measures that all PEO personnel should practice.
Ensure that the OPSEC program and OPSEC measures are coordinated and synchronized with security programs, e.g., information security (INFOSEC), information assurance (IA), physical security, and force protection.
Ensure that all official information released to the public, to include information released on the World Wide Web, receives an OPSEC review prior to dissemination.
Establish a documented OPSEC program that includes as a minimum, OPSEC Officer appointment orders and an OPSEC Plan.
Appoint an OPSEC officer in writing with responsibility for supervising the execution of proper OPSEC within the organization.
Ensure that the appointed OPSEC Officer is of appropriate grade or rank, and receives appropriate training in accordance with (IAW) Army Regulation (AR) 530-1, Operations Security (OPSEC), 19 April 2007.
Approve the PEO GCS Critical Information List (CIL) and circulate it to all subordinates as widely as security permits.
Provide guidance and direction to ensure that each subordinate organization understands, adapts, and applies the CIL to its mission and provides feedback.
Weigh the risk in the mission against the costs of protection and decide what OPSEC measures to implement; and publish such measures in the OPSEC Plan.
Senior Security Officer
Serve as the principal staff officer for overall management of the security and OPSEC program. The Senior Security Officer is the proponent for OPSEC, but the entire organization will integrate OPSEC into planning and execution of the organization’s activities.
Ensure the integration and synchronization of the OPSEC program with the OPSEC program of the Assistant Secretary of the Army for Acquisition, Logistics, and Technology (ASA(ALT)).
OPSEC Officer
Direct and implement the OPSEC program.
https://armypubs.us.army.mil/epubs/dr_pubs/DR_c/pdf/r530_1.pdf
Plan for and implement OPSEC before, during, and after operations and other activities, including RDT&E that affect the combat capability of the Army; ensure that OPSEC is part of the PEO’s initial planning guidance.
Chair the PEO-level OPSEC Working Group (OWG) to coordinate OPSEC actions across PEO GCS on a consistent basis.
Develop the PEO’s CIL in conjunction with other staff officers.
Develop and recommend OPSEC measures to be implemented within PEO
GCS.
Conduct OPSEC reviews of operational plans and reports to ensure adherence to OPSEC policies and procedures.
Conduct OPSEC assessments, in writing, of PMOs using the published OPSEC guidance to determine whether the PMO is implementing PEO-directed and their own OPSEC policies and procedures; recommend corrective actions as necessary.
Ensure that training exercises include realistic OPSEC considerations and that evaluation of training exercises includes evaluation of OPSEC procedures.
Further, ensure that pre-exercise OPSEC briefings incorporate the threat, CIL, and OPSEC measures.
Coordinate with the Public Affairs and Freedom of Information Act (FOIA) Officers to ensure that information concerning PEO GCS programs and projects is reviewed for OPSEC before being released.
Ensure that all OPSEC training is IAW AR 530-1 and this OPSEC Plan.
Integrate intelligence, counterintelligence, force protection, and Information Operations (IO) into OPSEC planning and practice.
Monitor the OPSEC programs of subordinate organizations by reviewing OPSEC Plans, survey results, exercise evaluations, and Inspector General reports.
Conduct an annual OPSEC assessment.
Prepare for the PEO’s signature the annual (by Fiscal Year) OPSEC Program Status Report to be submitted to the Army OPSEC Support Element (OSE).
Perform other duties and responsibilities as defined in AR 530-1, Appendix H.
Public Affairs Officer
Comply with Federal, Department of Defense (DoD), and Department of the Army (DA) website administration policies and implementing content-approval procedures that include OPSEC.
Consider OPSEC in preparation of all public releases of official information.
Coordinate with the OPSEC Officer before updating or posting information on all Web sites, IAW AR 25-2, Information Assurance, Rapid Action Revision (RAR) 001, 23 March 2009, paragraph 4-20.g.(11).
Ensure that in addition to the OPSEC Officer, the webmaster and other appropriate designees (e.g., command counsel, force protection, intelligence) have properly cleared information prior to posting to the web, unclassified intranet, or to Army Knowledge Online (AKO) areas accessible to all account types.
https://armypubs.us.army.mil/epubs/dr_pubs/DR_c/pdf/r530_1.pdf https://akocomm.us.army.mil/usapa/epubs/DR_pubs/DR_c/r530_1.pdf http://www.apd.army.mil/pdffiles/r25_2.pdf
Coordinate directly with the OPSEC Officer on all questionable releases and for additional guidance on any release, IAW AR 530-1, paragraph 2-3.a.(15).
Ensure that all military, civilian, or contractor personnel who post or maintain information (e.g., documents, spreadsheets) in the public domain for official PEO GCS purposes (also including OPSEC Officers and PAO personnel) complete “Social Media and Operations Security” training at Information Assurance Training Center or DISA’s Social Network Course; or such similar courses that may be required in the future
Ensure that all PEO personnel are aware of and support the OPSEC program, including OPSEC reviews IAW AR 530-1.
Consider OPSEC in all public affairs planning and execution procedures in support of antiterrorism (AT) efforts IAW AR 525-13, Antiterrorism, 11 September 2008, Appendix D.
Provide unclassified information about the Army and its activities to the public with maximum disclosure and minimum delay. Do not release information that would adversely affect national security, threaten the personal safety, or invade the privacy of members of the Armed Forces, IAW AR 360-1, The Army Public Affairs Program, 25 May 2011, paragraph 2-3.d.(5).
Webmaster
Comply with Federal, DoD, and DA website administration policies and implement content-approval procedures that include OPSEC and PAO reviews before updating or posting information on all websites IAW AR 25-2, paragraph 4-20,g.(11).
Conduct annual OPSEC reviews of all organizational websites and provide these results to the OPSEC Officer for inclusion in the annual OPSEC report IAW AR 25-2, paragraph 4-20.g. (15).
Coordinate directly with the OPSEC Officer for additional guidance on any questionable website posting.
Take the Social Media and Operations Security training course at Information Assurance Training Center or DISA’s Social Network Course.
Program Managers
Implement an OPSEC program.
Approve an OPSEC Plan specific to the operation of the PMO as a supplement to the PEO GCS OPSEC Plan.
Appoint an OPSEC Officer or Coordinator to perform those requirements of the OPSEC Officer that are appropriate for the PMO.
Ensure appropriate OPSEC measures are taken within the PMO to preserve essential secrecy.
Plan for and implement OPSEC before, during, and after operations and other activities, including RDT&E that affect the combat capability of the Army; ensure that OPSEC is part of the PM’s initial planning guidance.
https://armypubs.us.army.mil/epubs/dr_pubs/DR_c/pdf/r530_1.pdf https://ia.signal.army.mil/sms.asp https://ia.signal.army.mil/sms.asp http://iase.disa.mil/eta/sns_v1/sn/launchpage.htm https://armypubs.us.army.mil/epubs/dr_pubs/DR_c/pdf/r530_1.pdf https://armypubs.us.army.mil/epubs/dr_pubs/dr_b/pdf/r525_13.pdf http://www.apd.army.mil/jw2/xmldemo/R360_1/head.asp http://www.apd.army.mil/pdffiles/r25_2.pdf http://www.apd.army.mil/pdffiles/r25_2.pdf http://www.apd.army.mil/pdffiles/r25_2.pdf https://ia.signal.army.mil/sms.asp https://ia.signal.army.mil/sms.asp http://iase.disa.mil/eta/sns_v1/sn/launchpage.htm
Provide annual reminders of the importance of sound OPSEC practices, including but not limited to OPSEC news releases in publications, OPSEC information bulletins, and OPSEC awareness briefings.
Assistant Program Executive Officers
Ensure appropriate OPSEC measures are taken within the staff or section to provide maximum protection of all functions and activities.
Assist the OPSEC Officer with integrating OPSEC into all organizational activities.
All Personnel
Implement OPSEC measures as determined by the PEO.
Receive Operations Security Level I training IAW AR 530-1, Chapter 4, to— o Understand how OPSEC complements traditional security programs to maintain essential secrecy of U.S. military capabilities, intentions, and plans.
o Learn how to apply OPSEC to daily tasks.
o Learn why OPSEC is important to the organization.
o Understand how adversaries aggressively seek information on U.S.
military capabilities, intentions, and plans.
o Become knowledgeable of the local multidiscipline adversary intelligence threat.
o Become knowledgeable of PEO GCS critical information and how to protect it by applying OPSEC measures to prevent inadvertent disclosure.
Maintain need-to-know and telephone security.
Limit distribution.
Avoid talking about work in public locations.
Safeguard unclassified technical data (also known as Controlled Unclassified Information [CUI]).
Be familiar with this OPSEC Plan and where to obtain additional OPSEC guidance if needed.
Handle any attempt by unauthorized personnel to solicit sensitive or critical information as an incident per AR 381-12, Threat Awareness and Reporting Program, 4 October 2010. Report all such incidents immediately to the nearest supporting counterintelligence office and inform the chain of command.
OPSEC Considerations
All personnel will consider OPSEC when preparing policies, procedures, and doctrine;
when designing systems; and when prescribing logistic and administrative practices.
Policies, procedures, and doctrines govern the freedom of action and can introduce a degree of rigidity in the way functions are performed. Over time, the constraints imposed and procedural habits will become apparent, allowing adversaries to better http://www.apd.army.mil/pdffiles/r381_12.pdf predict what organizations will or will not do and how the organization carries out various functions.
Systems and tactics are of little value if an adversary develops the capability to locate, track, identify, target, and destroy the system or counter the tactic when it is deployed or implemented. Administrative and logistic practices are generally overt and can reveal information of considerable value to an adversary. Standard ways of executing tasks make it simple to detect changes in routines, or against a specific background, to detect capabilities being readied for use.
Critical Information
Critical information consists of specific facts about friendly intentions, capabilities, and activities vitally needed by adversaries for them to plan and act effectively to guarantee failure or unacceptable consequences for friendly mission accomplishment.
The OPSEC Officer, in conjunction with a working group, develops the PEO GCS overall CIL, which is then approved by the PEO. The PEO’s intent is that all personnel—military, civilian, and contractors—are aware of the organization’s critical information so they can better apply OPSEC to their daily tasks.
The overall PEO CIL is as follows:
Vulnerabilities and limitations in weapons and weapons systems – Operational limitations (weather, terrain); reliability or effectiveness of the weapon system; lack of performance or identification of damage against threat (e.g., ballistic, non-ballistic, nuclear, chemical, biological, electronic warfare)
Weapons systems development schedules below summary – Specific date, time, or location information prior to and during the event
Emerging technologies applicable to new weapons systems
Custom computer software used in weapons systems development, testing and evaluation
Identification of Critical Program Information (CPI) and Program Protection Plan (PPP) implementation methods – Location of CPI within the weapon system; identification of contractor developing CPI; protection measures implemented to protect CPI and critical functions of the weapon system
Specifics or requirements of the program in acquisition – Threshold and Objective specifications and technical performance measures
Preliminary programmatic and resourcing decisions not yet approved by the Army – Program or contract cancellations; pre-Program Objective Memorandum (POM) or Budget Estimate Submission (BES) lock budget data;
shortfalls in meeting program cost, schedule, and performance thresholds
Classification levels of the program – Special Compartmented Information (SCI) and Special Access Program (SAP) accesses; Security Classification Guide (SCG) identifies classified critical information; Department of Defense (DD) Form 254, if addressing SCI or SAP
OPSEC Measures
OPSEC measures are in place to protect identified critical information. A good way to evaluate an OPSEC measure is to start by considering its primary intended purpose and then consider any ancillary functions it performs. Since many OPSEC measures rely on their combination with other types of security functions it is helpful to ”round the bases” of the security diamond to determine all aspects of the OPSEC measure.
Possible OPSEC measures are as varied as the specific vulnerabilities they address.
OPSEC Measure Types
Example: Access control devices are physical security devices, but they rely on personal security procedures to dictate who should be allowed entry and who should be denied. Access control devices also rely on employee compliance with procedures to walk through such devices and to identify themselves by badge, ID number, or biometric measurements. If the employees do not uniformly comply with these procedures, the device is not effective. If an analyst accepts that access control hardware is effective by its very presence, he or she will have missed the true vulnerabilities in its effectiveness.
Information can be compromised in a variety of ways. Security education emphasizes the threat of overt and clandestine intelligence collectors. Conversations at work and off the job must not pertain to subjects that listeners do not have a need to know about.
Information security is of vital importance to the PEO GCS OPSEC program. Security procedures (e.g., using only approved storage containers, double-checking offices before departure, having a clean desk policy, ensuring the need to know) protect classified and sensitive program related information.
Personnel Procedural
Technical
Physical
OPSEC Officers and Coordinators will look at the total operations and activities and determine where in these operations and activities indicators of critical information are or can be collected by an adversary collection capability. After this determination, OPSEC Officers and Coordinators will determine the type of OPSEC measure that will counter or mitigate the adversary’s collection efforts. The actual measure or measures, in most cases, will be normal security or protective actions conducted by various security disciplines. By using the OPSEC process, described in AR 530-1, OPSEC Officers will determine who, what, when, where, why, and how to apply various measures. OPSEC officers will look at the total activity, as the adversary looks at the activity.
The measures identified here are not all-inclusive of those practiced in PEO GCS.
OPSEC measures in this section apply to all personnel at all operating locations. The OPSEC measures outlined in this section are designed to eliminate, reduce, or counter the possible vulnerabilities identified earlier in this plan. PMs will develop supplements to this Plan that address appropriate OPSEC measures, including those relevant to test activities, for their offices.
The PEO has selected the following OPSEC measures for implementation in ongoing activities and planning for future operations. OPSEC Officers and Coordinators will monitor these OPSEC measures. The process is continuous and will consider the changing nature of critical information, the threat, and vulnerabilities throughout all PEO GCS operations.
OPSEC Awareness
PEO GCS personnel will maintain compliance with the annual OPSEC and security training.
The OPSEC Officer or Coordinator will post OPSEC posters throughout facilities and rotate them on a quarterly basis.
OPSEC awareness efforts will include newsletters, email reminders, bulletins, etc.
The OPSEC Officer will remind all personnel that the enemy will exploit sensitive photos showing the results of improvised explosive device (IED) strikes, battle scenes, casualties, destroyed or damaged equipment, and killed enemies as propaganda and terrorist training tools.
The OPSEC Officer will inform all personnel of the danger of unwittingly magnifying enemy capabilities simply by exchanging photos with friends or relatives, or by publishing them on the internet or other media without proper OPSEC review.
All Personnel
Protect information that may have a negative impact on relations with coalition allies or world opinion.
Take reasonable steps to minimize risk of access to CUI by unauthorized personnel.
https://akocomm.us.army.mil/usapa/epubs/DR_pubs/DR_c/r530_1.pdf
Avoid displaying CUI in public places (e.g., airports, airplanes, restaurants).
Avoid open posting of planned schedule notices that reveal when sensitive events will occur.
Control the issuance of orders, movement of units, programs, or key personnel lists.
Protect information whenever you leave your desk. Whenever you step away, make a quick check to see whether there is sensitive information on your desk; if so, place it in a secure location off your desktop.
Be prepared to implement a ”clean desk“ on 1-hour notice in the event of visitors.
During periods of increased operational activity, follow the normal leave policy and working hours to the maximum extent possible to preserve the outward appearance of normalcy.
Ensure that discussions or releases to the media receive an OPSEC review.
Waste Disposal
Throwing information in the trash allows the adversary to retrieve it and gain information about our activities. The trash can is for non-informational items only (e.g., food waste, wrappers).
Destroy classified waste IAW applicable requirements. Use shredders or place unclassified information waste in shred bins located throughout PEO GCS facilities.
PEO GCS can shred CDs and DVDs in Building 229, Room 300-W, and the TACOM Life Cycle Management Command (LCMC) G-2 can degauss and destroy hard drives and other media (See IA BBP 03-PE-O-0003).
Conferences and Symposia
Personnel at conferences and symposia are susceptible to elicitation and exploitation by participants who covertly represent intelligence collection agencies. Without constant awareness of the threat and critical information, personnel may inadvertently release information of analytic value. PEO GCS personnel will complete an annual security briefing to remind them of the threat and of their security responsibilities. Additionally, the OPSEC Officer will make a continuing effort to keep personnel informed, via bulletins and guidance updates, of measures designed to protect sensitive program information and the need for continued awareness and enforcement of OPSEC principles. PEO GCS will attend a threat awareness brief from the local 902d Military Intelligence (MI) Group office prior to attending any conference or symposium known to be attended by foreign nationals.
Conference Room Security
The coordinator of any meeting on PEO GCS premises will work with the OPSEC Officer to ensure conference room security. Classified and sensitive information could be compromised by covert listening devices installed in meeting rooms. Unauthorized personnel may also gain entrance to larger meeting rooms and become exposed to information for which they do not have a need to know.
https://www.milsuite.mil/book/servlet/JiveServlet/download/36432-2-181369/Sanitization%20of%20Media%20BBP%2003-PE-O-0003.pdf
Meetings, briefings and conferences will be held in locations authorized for the proper clarification and sensitivity level.
The individual responsible for arranging the meeting will be responsible for the security of the meeting. The responsible individual will— o Notify the attendees of the classification or sensitivity of the meeting.
o Prepare the room for classified or sensitive discussion, e.g., unplug telephones, cover windows, clear adjacent rooms, turn off audio or video equipment not needed for the briefing, or ensure attendees were banned from bringing in portable electronic devices (PED).
o Ensure that each person attending the meeting has the appropriate access authorization by verifying invitee lists and controlling ingress and egress to the room during discussions and after each break.
o Ensure that notes taken are properly classified and marked and that arrangements have been made for the proper transmission of notes back to each attendee’s organization by verification of courier authorization or appropriate electronic transmission. If these measures are not feasible, the responsible individual will ensure that no notes are taken.
o Ensure that adequate storage facilities are available.
o Monitor the meeting to ensure that discussions are limited to the level authorized.
o Sweep the room after the meeting to ensure that no classified or sensitive material has been left behind.
PEO GCS security personnel will inspect conference rooms used to conduct classified meetings prior to use as part of their routine security procedures. Only conference rooms approved by the Security Manager are authorized for classified discussions.
Unsolicited Requests for Information
Intelligence collectors often use elicitation as a technique to discreetly gather information that could facilitate future targeting attempts. Elicitation techniques are usually non-threatening, easy to disguise, deniable, effective, and usable to obtain information on personnel, military installations, and government facilities. The conversation can be in person, over the phone, or in writing.
Know what information should not be shared, and be suspicious of people who seek such information. Do not tell people any information they are not authorized to know, to include personal information about you, your family, or your colleagues.
You can politely discourage conversation topics and deflect possible elicitations by—
Referring them to public sources (e.g., websites, press releases)
Ignoring any question or statement you think is improper and changing the topic
Deflecting a question with one of your own
Responding with "Why do you ask?"
Giving a nondescript answer
Stating that you do not know
Stating that you would have to clear such discussions with your security office
Stating that you cannot discuss the matter.
If you believe someone has tried to elicit information from you, especially about your work, report it to your OPSEC Officer.
Compromising Emanations
Electronic and electromechanical telecommunications and automated information processing equipment can produce unintentional, intelligence-bearing emanations. The study of these emanations is commonly known as TEMPEST. Interception and analysis of these emanations can disclose information transmitted, received, handled, or otherwise processed by the equipment. All Army facilities (including contractor facilities supporting the Army) electronically processing classified information must provide information to the TEMPEST Program Manager for a facility review to determine whether a formal TEMPEST Countermeasure Review (TCR) is required. A PEO GCS Security Manager will oversee these reviews and submission of this information on DD Form 254. If a contractor either receives or generates classified information or material via electronic means (blocks 11b and 11c), then block 11i will be checked YES and include the PEO GCS TEMPEST standard language, which identifies the process for contractors to submit a request for a TEMPEST review.
Communications Security
The Army is very concerned about the vulnerability of voice communications. The threat to the national security is real and it is current. All unsecured telephone conversations are vulnerable to monitoring, and all long-distance microwave transmissions are subject to intercept. Such vulnerabilities provide a rich source of information to intelligence agents. To effectively counter the threat to voice communications, all personnel will take the following OPSEC measures:
Classified or sensitive information will not be discussed over an un-secure telephone or network. Each employee will carefully consider the security implications of any information to be discussed and use only approved secure means to discuss classified or sensitive information. All personnel will use the Secure Telephone Equipment (STE) in the encrypted mode whenever necessary, particularly when discussing any technical information. If an STE is not available, Defense Connect Online (DCO) is an alternate secure option when used with a headset or in a conference room using the conference room security identified above. DCO is encrypted to DoD-mandated levels of security and is housed in DISA’s secure computing facilities. DCO is available to anyone with a Common Access Card (CAC) and to individuals sponsored by a CAC holder (with registration). Training is available from a PEO GCS Security Manager for the operation of STE phones and DCO. STEs will only be in restricted access areas, to avoid the compromise of critical information. Use of STEs will comply with the STE User Brief provided by the local COMSEC Custodian.
http://www.dtic.mil/whs/directives/infomgt/forms/eforms/dd0254.pdf http://www.dtic.mil/whs/directives/infomgt/forms/eforms/dd0254.pdf
Personnel will maximize the use of secure communications, telephone, fax, classified email, U.S. Message Text Format messages, or Public Key Infrastructure (PKI) enabled computer networks; and not attempt to “talk around” classified information by using code words, catch phrases, or other double-talk. Taken alone, an individual conversation might not result in a compromise of classified information, but when placed in a sequence of several conversations that may occur over several days, the possibility of compromise becomes very real.
When sending sensitive information via a unsecure facsimile machine, personnel will coordinate the transmission and receipt of information prior to faxing to ensure the information does not remain unattended on the receiving end of the transmission. This coordination should include immediate confirmation of receipt by the recipient upon retrieval of the information.
All personnel will store, use, and destroy issued COMSEC material IAW AR 380-40, Safeguarding and Controlling Communications Security Material, 9 July 2012, and TB 380-41.
All personnel will limit mission-related email to only “.mil” and “.gov” accounts.
Transmission of sensitive information or CUI will only be via encrypted email.
Computer Security
The nature of PEO GCS operations requires extensive use of computer equipment.
Without adequate security measures, this equipment is susceptible to intrusion or tampering through hardware or software manipulation. Personnel will only process classified information on computer systems that have been approved by the Designated Approval Authority (DAA) IAW AR 25-2 or, in the case of contractor systems, approved by the Defense Security Service (DSS) IAW the National Industrial Security Program Operating Manual (NISPOM).
In addition, the following measures will protect unclassified sensitive information or CUI:
Physically protect computer systems from intrusion or tampering by keeping them in PEO GCS facilities.
Include Data-At-Rest encryption on laptops.
Avoid processing CUI on public computers (e.g., those available for use by the general public in kiosks, hotel business centers) or computers that do not have access control, including personally owned computers.
Physically protect mobile devices used to store CUI electronically (e.g., PEDs, removable media) and use NIST or NIAP-approved cryptographic products.
These are available at ECA PKI Program or NIST Security Management & Assurance.
https://armypubs.us.army.mil/epubs/DR_pubs/DR_b/pdf/r380_40.pdf http://www.apd.army.mil/pdffiles/r25_2.pdf http://www.dss.mil/documents/odaa/nispomIndex_feb2006.pdf http://csrc.nist.gov/groups/STM/index.html http://www.niap-ccevs.org/ http://iase.disa.mil/pki/eca/ http://csrc.nist.gov/cryptval/ http://csrc.nist.gov/cryptval/
Employee Travel
PEO GCS personnel are susceptible to elicitation and exploitation during travel by individuals who covertly represent the intelligence collection agencies of foreign governments. Collection efforts may range from innocuous questions from friendly inhabitants to actual blackmail by intelligence agents, electronic monitoring, document duplications, and actual theft of material. Without constant awareness of the threat and the CIL, personnel may inadvertently provide sensitive information of analytic value to foreign intelligence agents. The OPSEC Officer will provide periodic security briefings to PEO GCS personnel as part of the continuing OPSEC awareness effort, which also includes bulletins and OPSEC guidance updates of measures designed for the protection of sensitive program information and the need for continued awareness and enforcement of OPSEC principles. OPSEC measures for travel include the following:
Travel in civilian clothes whenever possible. Do not carry bags or other items that identify you as a member of PEO GCS or the Army.
Use a passport instead of military orders whenever possible.
Do not discuss assignments, duties, or reasons for travel unless absolutely necessary (e.g., with security, customs, or immigration personnel).
Comply with PEO GCS Policy for Traveling Outside the Continental United States (OCONUS) with Government Furnished Equipment (GCS-12-007), 7 June 2012.
Shipment of Sensitive Materials
When shipping sensitive material, personnel will consider the safety of the shipment method and review the label markings for sensitive information. Not only are shipments of sensitive material subject to interception, but labels placed on packaging can sometimes reveal information of analytic value.
Public Release
Personnel will not discuss, show or make available safeguarded information to unauthorized individuals. The OPSEC Officer will review information, materials, or records IAW AR 530-1 prior to public release. The only approval authority other than the PEO to release PEO GCS information to the public is the PEO GCS PAO. Follow the PEO GCS Public Release process to obtain approval for release of information.
Website OPSEC Reviews
The internet and intranet allow PEO GCS to further increase distribution of print and broadcast mediums to reach a wider audience. Creators and designers of this material will ensure it meets OPSEC requirements. PEO GCS integrates OPSEC reviews of its websites into the overall OPSEC program and includes it in their annual OPSEC Program Status Report to OSE. The OPSEC Officer will work with the PAO and Webmaster to ensure that website owners do the following:
https://kcp.tacom.army.mil/policy/PolicyDocs/PEO%20GCS%20OCONUS%20Travel%20Policy%20with%20Gov't%20IT%20Equipment.pdf https://kcp.tacom.army.mil/policy/PolicyDocs/PEO%20GCS%20OCONUS%20Travel%20Policy%20with%20Gov't%20IT%20Equipment.pdf
Verify a valid mission need to disseminate the information to be posted.
Vet information via the PEO Public Release process prior to posting information to the website.
Protect information according to its sensitivity, and ensure reviewing officials and webmasters are selected and have received appropriate training in security and release requirements IAW Army web policy.
Security Managers, PAOs, and webmasters will use the PEO checklist to review content quarterly on their publicly accessible websites.
Employee Disaffection
Supervisors or fellow employees should report individuals to the PEO Security Office who, through personal adversities or circumstances (e.g., marital difficulties, criminal or non-acceptable social behavior, excessive indebtedness, indiscriminate use of alcohol or drugs) present an attractive target to foreign intelligence agencies. Non-action on the part of personnel who become aware of these situations can be as significant a threat as that presented by a foreign agent who may attempt to exploit personnel experiencing these problems.
Document Markings
All documents containing PEO GCS information will be marked appropriately by the author upon creation. Proper use and application of markings to indicate classification or the presence of CUI are necessary to identify the proper protection and who is authorized to receive the information. Classified information will be marked IAW DoDM 5200.01, Vol. 3, to identify the level of protection and dissemination of the information.
CUI is identified in the Security Classification Guides and DoDM 5200.01, Vol. 4, as well as below.
The For Official Use Only (FOUO) designation encompasses unclassified information that is eligible for exemption from mandatory public disclosure under the FOIA. FOUO information includes commercial or financial information generated by or for the Government with the understanding that it is on a privileged or confidential basis (e.g., bids, contracts, proposals, trade secrets, inventions, discoveries, proprietary data, data on contract performance). When identified in the SCG or instructed by the Security Office, material will be marked FOUO. This information is excluded from public release;
however, information is not excluded or marked FOUO merely because it is OPSEC sensitive. To qualify for marking as FOUO, information must fall under one or more of the exemption categories specified in AR 25-55, The Department of the Army Freedom of Information Act Program, 1 November 1997. Marking instructions are in the SCG or
AR 25-55.
Technical data is any recorded information related to experimental, developmental, or engineering works that can be used to define an engineering or manufacturing process, or can be used to design, procure, produce, support, maintain, operate, repair, or overhaul program material. The data may be graphic or pictorial delineations in media (e.g., computer software, drawings, photographs), text in specifications, related http://www.dtic.mil/whs/directives/corres/pdf/520001_vol3.pdf http://www.dtic.mil/whs/directives/corres/pdf/520001_vol3.pdf http://www.dtic.mil/whs/directives/corres/pdf/520001_vol4.pdf http://armypubs.army.mil/epubs/pdf/r25_55.pdf http://armypubs.army.mil/epubs/pdf/r25_55.pdf performance or design documents, or computer printouts. Examples of technical data include research and engineering data, engineering drawings, and associated lists, specifications, standards, process sheets, manuals, technical reports, catalog-item identifications, and computer software documentation. PEO GCS personnel will protect technical data by applying a distribution statement to limit the dissemination of the information. An export control warning notice may also accompany the distribution statement. Marking instructions are in the SCG or Department of Defense (DoD) Instruction 5230.24, Distribution Statements on Technical Documents, 23 August 2012.
CUI Protection Measures
CUI protection measures include the following:
Release CUI only to an individual who is a U.S. person and has a valid need for such access in connection with the accomplishment of a lawful and authorized Government purpose.
Handle CUI material to prevent its disclosure to the general public and to limit its circulation to those employees who need the material to perform their work duties
Do not leave CUI material unattended when removed from storage.
After working hours, store CUI information in locked desks, file cabinets, bookcases, locked rooms, or similar means.
Do not display CUI in public places, such as airports, airplanes, restaurants, etc.
Do not process CUI on public computers (e.g. those available for use by the general public in kiosks, hotel business centers) or computers that do not have access control, including personally owned computers.
Protect CUI stored electronically on portable devices (e.g., laptops,…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .